Push User account from IDM to LDAP

Hi,
I need to push the new users created in IDM to LDAP. I created a rule library specifying the attributes that need to bu pushed and am calling that library in create user workflow.
However, the new user and related attributes are not being pushed to LDAP. Can somebody point out the mistake in my code?
Here is the Rule Library:
<Extension>
<Library>
<Comments>rule library that contains all rules</Comments>
<Rule name='RULE_create_LDAP_Acct'>
<RuleArgument name=''/>
<block trace='true'>
<set name='user.accounts[LDAP1].firstname'>
<ref>firstname</ref>
</set>
<set name='user.accounts[LDAP1].lastname'>
<ref>lastname</ref>
</set>
<set name='user.accounts[LDAP1].accountId'>
<ref>accountId</ref>
</set>
<set name='user.accounts[LDAP1].email'>
<ref>user.waveset.email</ref>
</set>
</block>
</Rule>
</Library>
</Extension>
<MemberObjectGroups>
<ObjectRef type='ObjectGroup' id='#ID#Top' name='Top'/>
</MemberObjectGroups>
</Configuration>
Here is the change i made to provision activity in create user workflow:
<Activity id='4' name='Provision'>
<Comments>&#xA; Perform the standard Lighthouse provisioning process.&#xA; </Comments>
<Action id='0' process='Data Transformation'>
<Comments>Apply any defined data transformations</Comments>
<Argument name='ruleName'>
<ref>transforms.preProvisionRule</ref>
</Argument>
<Argument name='formName'>
<ref>transforms.preProvisionForm</ref>
</Argument>
</Action>
<Action id='1'>
<expression>
<cond>
<eq>
<ref>sunrise.createResourceAccounts</ref>
<s>true</s>
</eq>
<block>
<set name='options.targets'>
<List>
<String>LDAP1</String>
</List>
</set>
<set name='user.waveset.resources'>
<filterdup>
<appendAll>
<ref>user.waveset.resources</ref>
<list>
<s>LDAP1</s>
</list>
</appendAll>
</filterdup>
</set>
</block>
</cond>
</expression>
</Action>
<Action id='2' name='Create LDAP Account'>      
<rule name='RULE-LIB-xxx:RULE_create_LDAP_Acct'>
<argument name ='firstname' value='$(firstname)'/>
<argument name='lastname' value='$(lastname)'/>
<argument name='email' value='(email)'/>
</rule>
</Action>
Any help is appreciated.
Thanks,

Ankush,
I am having this problem only when trying to assign LDAP to a user through the WF. No problems whatsoever while doing it manually.
I tried creating a contained users under people and modified identity template accordingly. But no luck..the same Error Code 32.
I have 3 required attributes in the mapping, cn,sn and uid. The obejct classes i ahve are top,person,organizational person and inetOrgPerson.
The only modification i made to create user WF is add this action under provision:
<Action id='2' name='Create LDAP Account'>      
<rule name='Create LDAP Account'>
<argument name ='firstname' value='$(firstname)'/>
<argument name='lastname' value='$(lastname)'/>
<argument name='email' value='$(email)'/>
</rule>
</Action>
The Rule is as follows:
<block>
<set name='user.waveset.accountId'>
<ref>accountId</ref>
</set>
<set name='user.accounts[Lighthouse].accountId'>
<ref>accountId</ref>
</set>
<set name='user.waveset.resources'>
<filterdup>
<appendAll>
<ref>user.waveset.resources</ref>
<s>LDAP1</s>
</appendAll>
</filterdup>
</set>
<set name='user.waveset.assignedLhPolicy'>
<s>LighthouseAccountPolicy</s>
</set>
<set name='user.waveset.firstname'>
     <ref>firstname</ref>
</set>
<set name='user.waveset.lastname'>
     <ref>lastname</ref>
</set>
<!-- <set name='user.waveset.email'>
     <ref>email</ref>
</set> -->
<set name='user.waveset.organization'>
<s>Top</s>
</set>
<set name='user.waveset.accounts[LDAP1].created'>
<s>true</s>
</set>
</block>
</Rule>
Please let me know if something is wrong with this.
Thanks,

Similar Messages

  • How to classify new and old user account from idm system using SPML

    hi all,
    i can use SPML code to create new user on IDM system but, i can't classifying new or old user account
    any advise ? very thank you in advanced.
    athikom.

    Hi Vikram,
    Iam not sure though, did you chekced EXIT_SAPMM06E_022 if it helps you in anyway.
    Regards,
    Swarna Munukoti

  • How to copy a user account from one Mac to another

    If I have a main user (admin) account on one Mac, and want to copy its Home Folder over to another Mac that already has user accounts on it, what is the best way to do it?
    For example, if I boot the source Mac in Target Disk Mode then connect it to the other Mac, can I just drag and drop from its Users folder into the Users folder on the other Mac? And would that then appear in SysPref/Accounts, complete with names and passwords etc, or is it not that simple?
    (Actually, I just checked by launching Migration Assistant, and it seems to indicate I can use it to copy User Accounts from a different Mac - is this all I need? How would I connect the two Macs for this to work?)

    Slightly confusing, that article - it talks about using Migration Assistant in Lion or Mountain Lion, but in my case both computers have used Snow Leopard. Does it still apply?
    (One other observation - don't you find it confusing the way Apple defines "Target Disk Mode"? It's pretty much always the case that a computer booted in this way becomes the Source computer, while the Target computer is the one it's connected to!!)

  • Copy a user account from one disk to another

    I replaced the hard drive in my G5 imac, and for one reason or another, using restore failed to create a bootable disk. Instead, I reinstalled Leopard. I would like to copy the old user account from the old hard drive so I can seamlessly continue using my computer. I created a secondary account on the new drive with the same name as the old one, and then copied the contents, but that didn't work very well.
    Can you advise how to restore the account from an old disk for use on a new one?

    Well, the desktop picture was generic, opening firefox gave me the error along the lines of "cannot open firefox, firefox is already open." Trying to download a new firefox tells me that there's no room on the disk. That's about where I stopped. Pretty much everything isn't working right.

  • Create Oracle USER Account from Third Party System

    Hi there
    We have requirment to create Oracle USER Account through third party system.
    How can we achive this?
    I know ORacle Provide FND_USER_PKG.CREATEUSER API to create user
    Is there any special thing we have to do to create Oracle USER from another system?
    Thanks
    ASIM

    Hi,
    Is there any special thing we have to do to create Oracle USER from another system?I believe you need to check the third party manual or contact the vendor for other considerations when creating user accounts from this system.
    For FND_USER_PKG, please see the links referenced in this thread.
    change password of EBS user
    Re: change password of EBS user
    Regards,
    Hussein

  • How to transfer user accounts from Active Directory to Open Directory

    Please help me , want to tranfer user accounts from Active Directory (Windows server 2012 ) to Open Directory (OS X server 10..2.9)

    Hi,
    Go to the advanced administration for the OSX Server:
    https://help.apple.com/advancedserveradmin/mac/3.1/#apd6D7FE39D-32AA-400C-91E1-5 0ABC15655C8
    This pretty easy way of connecting your server to the Windows server should give AD users access to OD services. That will be a good start.
    Read up on this as well:
    http://support.apple.com/kb/PH15469
    Do you want to import them all or just the Mac users?
    Goodluck!
    Jeffrey

  • How do I run a user account from an external HD?

    How do I run a user account from an external HD? I will be away from my desktop iMac and want to use our MacBook Pro overseas for two months with my iMac user account copied to an external drive.

    1. WARNING: This procedure is for advanced users only. Some third-party software may not work as expected, or may not work at all, if the home folder is moved.
    2. Back up all data.
    3. Copy your home folder to the desired location, which must be on a volume of type "Mac OS Extended (Journaled)" with file ownership enabled, as shown in the Finder Info dialog. Encryption is optional. The volume must be on a local storage device, not on the network, and it must be mounted automatically at startup — before any user logs in. A disk image will not work.
    The name of your home folder is your short user name. Do not rename it. Do not copy the "Users" folder.
    5. Select
     ▹ System Preferences ▹ Users & Groups
    Click the lock icon and authenticate. Right-click or control-click your name in the account list, and select Advanced options from the popup menu. In the sheet that opens, change the location of the home directory. Log out and log back in.
    6. Test. If you have problems, reverse the above steps. If you got this far, you should have no trouble doing that. If everything works as you expect, delete the original home folder.

  • Migration Assistant Won't Migrate User Account from Time Machine

    I am trying to move my wife's user account from a Time Machine backup using Migration Assistant.  Migration assistant chugs along for 2 1/2 hours and says everything was transfered hunkie-dorie.  However, when I try to log her on, I can't.  When I log on as me, I went to System Prefs --> Accounts, her username is there.  However, when I look inside the Users folder, none of her information is there.
    thanks in advance,
    tim

    No Filevault on my computer and hers.
    Doesn't work in Save Boot, either.  That is the puzzle.  Her account appears at the login screen--even the flower pic. that was migrated from from the Time Machine backup. The login screen will not accept any password.  I know I'm typing it correctly.  Her account appears in System Prefs --> Users, but it's not in the Users folder on my disk drive.
    tim

  • Can't get user account from 10.7.5 to Mavericks with Migration Assistant

    I am perplexed about this one.  I want to use migration assistant to get a user account from an old Mac Pro running 10.7.5 to a 2012 iMac that has Mavericks on it.
    I've tried:
    1 - Migration assistant over the network - migration assistant says the Mac Pro needs a higher operating system, but the computer can't be upgraded.
    2 - Target mode of Mac Pro to iMac: Migration assistant sees the volume, but doesn't acknowledge any user accounts.  It only acknowledges applications, and other files.
    Any ideas folks.  I simply want to bring the user accout over to the new computer and perhaps the applications.

    LOL - I figured it out.  I had to update the Mac Pro which included a new migration assistant update.

  • Excluding temporary user accounts from Time Machine back-ups

    I have some temporary user accounts in addition to the default Guest account on my iMac. I currently have Time Machine backing up my entire system (the default TM setup). However, I'd like back up only my admin and permanent user accounts from now on.
    Having done a little research, I believe I have the answer but want to make sure I'm including all the relevant directories. I believe the answer is to add the specific user folders to TM Preferences > Options > Do Not Backup. e.g., if my hard disk is named "MacintoshHD" and I want Users 'Account1' and 'Account2' to be excluded from all future TM backups, I would add these folders to the Do Not Backup folder:
    /MachintoshHD/Users/Account1
    /MachintoshHD/Users/Account2
    So 2 questions:
    1. Are these the right folders to make sure Account1 and Account2 are never backed up in the future?
    2. Are there any other folders that i am overlooking?
    Is that correct? Thanks in advance for your help!

    Jeff Hwang wrote:
    I have some temporary user accounts in addition to the default Guest account on my iMac. I currently have Time Machine backing up my entire system (the default TM setup). However, I'd like back up only my admin and permanent user accounts from now on.
    Having done a little research, I believe I have the answer but want to make sure I'm including all the relevant directories. I believe the answer is to add the specific user folders to TM Preferences > Options > Do Not Backup. e.g., if my hard disk is named "MacintoshHD" and I want Users 'Account1' and 'Account2' to be excluded from all future TM backups, I would add these folders to the Do Not Backup folder:
    /MachintoshHD/Users/Account1
    /MachintoshHD/Users/Account2
    So 2 questions:
    1. Are these the right folders to make sure Account1 and Account2 are never backed up in the future?
    yes.
    2. Are there any other folders that i am overlooking?
    no, those are the only folders you need to exclude.
    Is that correct? Thanks in advance for your help!

  • Restoring user accounts from system install backup directory

    Hi,
    I had some kind of disk problem that forced me to reload tiger. When tiger intalled it backed up all of the user directries. After the new install booted up I can not figure out how to restore all of my user accounts from this backup directory. Maybe I am making it too hard (ex PC user). The migtration utility only wants to restore off a Mac or different volume. Any suggestions?
    Thanks
    imac g4 800   Mac OS X (10.4.6)  

    If you did an Archive & Install, then you should have selected the saving user and network settings. Otherwise, everything was put into the Previous System folder. IIRC, you need to recreate the users, using the exact same username and password combinations. Then, log into each account, open the corresponding folder within the Previous System/Users/ directory and transfer everything from the old account to current account.

  • How do you delete a guest user account from the users&groups pane?

    could anyone help with giving a tip on how to  delete a guest user account from the users&groups pane in os-x 10.7 ? when I unlock account the delete or minus button is inactive. Thankyou

    aha, by disabling the find my mac checkbox in icloud seems to work. tusen takk previous threaders!!!!!!!!!!

  • Restore Filevault enabled user account from Timecapsule?

    My imac running Snow Leopard crashed but was backed up to my Time Capsule.
    The guy at the Apple store just erased & re-loaded the OS and said my timecapsule was still in tact after the crash.
    I tried using migration assistant at home to re-load my mac as it was before the crash from Timecapsule but it says I cannot transfer my user account because it was encrypted with filevault???
    PLEASE HELP! My entire life is on this computer and the ONLY reason i got a timecapsule with the new imac was so I could restore everything with one click after a crash!
    (as a side note my 5 1/2 year old macbook running OS X Lion crashed with the latest update and subsequently it's hard drive died at the same time! so I'm completely screwed if I can't restore my user account from time capsule.
    HELP!!!

    KingaMLK wrote:
    I tried repairing disk permissions, repairing disk
    But did you repair your backups?
    That's a different thing.  If they're corrupted, it could explain the problem you're having; if we can repair them, the full system restore may work.
    The difficulty here is, you can repair an internal or external HD by starting from your Snow Leopard Install disc and using Disk Utility.  But to repair the sparse bundle on a Time Capsule, you must be able to log on to your Mac with a (any) user account, and locate the sparse bundle via the Finder to mount it first.
    Since you apparently have a restore attempt running now, don't interrupt it.
    But if it doesn't work, or you can't find all your data, and if you can log on to your Mac with any account, try repairing the backups per #A5 in Time Machine - Troubleshooting.

  • Push user accounts to LDAP

    Hello Experts,
    We have setup E-Sourcing 5.1 connected to a MS AD server as LDAP. This LDAP was created exclusively for E-Sourcing application.
    We want to try a scenario where the user administration is handled only by E-Sourcing system, and credentials and passwords are stored in the LDAP. Note that this means that there won't be any user Administration in LDAP, it would be done through e-Sourcing. Is this possible?
    We tried creating "New Accounts" in the LDAP by creating a new user in E-Sourcing, but so far it's been unsuccessful. We get a "driver error" in the ESO UI. It seems the system requires the account to be previously created in LDAP so it can be created in E-Sourcing.
    Has anybody tried doing this?
    Your help is appreciated.
    Regards,
    Gilberto Gallardo

    Hi Gilberto,
    If I understand correctly, when you create a new user account in Sourcing, you want Sourcing to create that account in LDAP as well. This should be possible. I would check if the right Driver is selected in the Directory Configuration. Also, make sure the LDAP related fields on the Directory Configuration such as Host, Port, Directory User Name, Password, BASE DN, etc. has the right values.
    Also, can you provide more details on the error message? I would check the Sourcing logs, it should contain more information on the error.
    Once the account is successfully created in LDAP, the attributes on the directory configuration can be set to push or pull depending on what is desired.
    Regards,
    Vikram

  • **want to create a user account from "Crypted Password" to "Open Directory"

    I have create a user account with "user password type: Crypted Password"
    is there any way I can script it to "user password type: open directory"
    I've use perl-ldap to create user account but I don't know how to change user password type to open directory,
    because my script will add a new node in the directory, I just need a way to make the "user password type" to "Open Directory" AT CREATION TIME, not modifing it after a have a user account, the script below will generate a node in the directory with "Crypted Password" as User Password Type,
    is there any attribute I need to add to make it "Open Directory" or perl command, applescript, bash, objective c(hopefully not)....
    thank for reading...
    $res = $c->add(dn => 'uid=testing,cn=users,dc=microsoft,dc=info',
    attr => [
    'cn' => 'testing',
    'gidNumber' => '20',
    'homeDirectory' => '99',
    'objectclass' => 'inetOrgPerson', 'posixAccount', 'shadowAccount', 'apple-user', 'extensibleObject','organizationalPerson','top','person',
    'sn' => 'testing',
    'uid' => 'testing',
    'uidNumber' => '5000',
    1. 'apple-generateduid' => '27318931-B341-4364-91B4-84E4AAAD1234', #026F",
    'givenName' => 'testing',
    1. 'loginShell' => '/bin/bash',
    'userPassword' => 'testing' ,
    1. 'homePhone' => '555-2020',
    2. 'mail' => '[email protected]'
    die "unable to add, errorcode #".$res->code().$res->error if $res->code( );
    thanks

    Since this question isn't Xserve specific a better place to get an answer is probably in the Directory Services forum: http://discussions.apple.com/forum.jspa?forumID=1353
    That being said if you are trying to migrate Crypt accounts to OD accounts then the short answer is no. You need an unencrypted password to put the password into OD via a script do short of cracking the encrypted password, inserting it in plain text into the OD user account creation process then I don't think you can.
    You should be able to dictate the password (and any other settings you can do from the GUI) but the password is the missing piece. Under really old OS X systems I actually suspect you can get passwords to export (hinted at by an Apple engineer I discussed this with) but there is probably a faster and more straightforward solution.
    What I have done is export from NetInfo, clean the accounts via script and then reimport the accounts into the new system. I usually assign a password and dictate "Must change password at next login" and then email people the temporary passwords. It's been a while but I believe you can mass select and then dictate password settings so if that works for you create accounts with all the same password and then you can select by group and make changes - eg Must change password at login.
    Good luck,
    =Tod

Maybe you are looking for

  • Help getting to Mac OS X

    My iMac got a virus on the windows side of the computer that wouldn't allow me to switch to the Mac OS. After trying many things to get to the OS X side I eventually reformatted both of the partitions in to one. The problem now is that when the iMac

  • Multiple pages in scripts.

    Hi , Could you please tell me how is multiple pages trigerred in scripts. Say the second page. Is this done through the print program? Are there any specific control commands to do so? <<text removed by moderator>> Thanks in advance, Suchi. Edited by

  • Good case for MBA 13 inch

    I need a good case for my MBA that can survive a bus ride to and from school

  • Can't get my new page to work wit my website

    I know html but I can't get this to work. I have a website and I am trying to ad a new page to it. I can't get it to work. I have checked it link and it is fine. Must be something with the page. I don't know. Can anyone help me.

  • {module_categorylist} Categories drop down show sub categories only

    Hi On this page I have a FAQ search at the top of the page. http://www.pantheraaccounting.co.uk/features/faqs In the 'Categories' drop down I have a set of sub Categories called 'FAQ' - is there anyway I can just show the subset of categories instead